What happened
On September 16, 2026, Gyazo published its notice confirming unauthorised access and external exposure of user information and image metadata. On September 18, 2026, wider reporting brought the confirmed scale and private-image uncertainty into the Friday enterprise-security cycle. Gyazo says it blocked the access paths, fixed the vulnerability and continues to investigate scope and secondary harm.
Gyazo confirmed exposure relating to approximately 23.62 million users, metadata for approximately 490 million images and approximately 2.4 million additional image-metadata records obtained under separately narrowed conditions. Potentially exposed user fields include email addresses, password hashes, device IDs, login session IDs, profile data, X integration tokens and Google SSO email addresses.
Image metadata may include source IP addresses, User-Agent values, EXIF location information, OCR text, titles, source URLs and passphrase hashes for private images. Gyazo confirmed that a list of private image files was obtained and said it cannot rule out that some private images were viewed. Gyazo says payment information was not exposed and passwords were represented by hashes rather than plaintext.
Attribution posture: Gyazo confirms unauthorised third-party access but does not identify or attribute the responsible actor. No actor identity, precise unauthorised-access timeline or confirmed count of private images viewed was published in the cited sources. The company plans staged contact with potentially affected users, while anonymous or otherwise unreachable accounts may receive information through the service interface. The cited source did not publish the actor-attribution detail described as Missing actor and access detail.
Why this matters now
The exposed fields go beyond ordinary profile data. Session identifiers, device identifiers, password hashes, integration tokens, OCR text, source URLs, IP addresses and location metadata can support account targeting, impersonation or intelligence gathering even when payment-card details were not exposed.
Gyazo is often used as an informal productivity tool rather than a centrally governed system of record. That operating model makes exposure discovery difficult: security may not know which employees used it, what screenshots contained or whether private links were embedded in tickets, chat systems, documentation and customer communications.
The company has not confirmed that image files were broadly taken, but it cannot rule out viewing of some private images and says information used to construct image URLs was exposed. Enterprises should therefore separate confirmed database exposure from unresolved content exposure and preserve both possibilities in legal, privacy and incident decisions.
The decision for security leaders
Treat Gyazo as a potentially unmanaged third party until organisational use is measured. Procurement records alone may miss individual accounts, browser extensions or screenshots shared through other collaboration systems.
Separate identity containment from content assessment. Password resets and token revocation address account risk; determining what screenshots and metadata reveal requires application owners, privacy staff and business teams.
Maintain a defensible disclosure posture based on confirmed enterprise use and data content. Gyazo’s aggregate figures do not establish that a particular organisation’s screenshots or users were affected, so decisions should follow evidence rather than the headline count.
Evidence of closure
- Account inventory identifies every business user and responsible data owner.
- Credential and token revocation is validated through new-session testing.
- Screenshot-content review records approved dispositions for sensitive data exposure.
- Legal assessment documents notification decisions and remaining evidence limitations.
The Security.io assessment
Gyazo’s primary notice is unusually specific about affected data classes and aggregate quantities, supporting high confidence that material user and image metadata left the service boundary. The unresolved question is the degree of actual private-image access and subsequent misuse.
The incident is most consequential for organisations that adopted Gyazo informally. Screenshot services can accumulate credentials, administrative consoles, customer records, source code and incident evidence without appearing in standard data inventories, making retrospective scoping labour-intensive.
Gyazo confirmed that a list of private image files was obtained and said it cannot rule out that some private images were viewed. Gyazo says payment information was not exposed and passwords were represented by hashes rather than plaintext. No actor identity, precise unauthorised-access timeline or confirmed count of private images viewed was published in the cited sources.
Questions for the morning meeting
- Do employees use Gyazo to capture credentials, customer data or internal systems?
- Can we identify corporate accounts created outside approved SaaS procurement?
- Which exposed session or integration tokens require enterprise-side revocation?
- Does the incident create contractual, privacy or customer-notification duties for us?